
Researchers Use Claude AI to Port Pre-Auth RCE Exploit Between WAGO PLC Models
Industrial Control SystemsVulnerability ExploitationArtificial IntelligenceRemote Code Execution
Forescout Research - Vedere Labs used Anthropic's Claude AI to port a working pre-authentication remote code execution exploit from one WAGO programmable logic controller (PLC) model to another. The exploit targets CVE-2021-31886, a stack-based buffer overflow vulnerability in the Nucleus FTP server's handling of the USER command. The researchers successfully executed attacker-supplied ARM shellcode on live hardware using the AI-ported exploit.